CVE-2022-31670
CVSS 3.1 Score 7.7 of 10 (high)
Details
Summary
CVE-2022-31670 vulnerability affects Harbor, an open-source container registry. The issue lies in Harbor's failure to validate user permissions when updating tag retention policies. An attacker can exploit this flaw by attempting to update a tag retention policy with an id belonging to a project the user doesn't have access to. By doing so, the attacker could modify tag retention policies in other projects, compromising their data retention settings. This vulnerability poses a significant risk, especially in multi-tenant environments, and requires immediate patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.